Egret Nest · Changelog

What shipped in Egret Nest.

Released changes for the dashboard, synced from the repo. See the roadmap, or the Egret agent changelog.

Changelog

Notable changes to Egret Nest Dashboard, following Keep a Changelog and Semantic Versioning.

[0.2.0] - Security hardening (pentest remediation)

Changed (upgrade impact)

  • The server refuses to start without EGRET_NEST_SECRET_KEY when TOTP data would otherwise be stored unencrypted. Set the key, or explicitly opt into the old behavior with EGRET_NEST_ALLOW_PLAINTEXT_TOTP=1. This was previously a warning that silently continued with plaintext TOTP seeds at rest.
  • SSO login is refused until first-run setup is complete. A brand-new SSO account can no longer be auto-provisioned before the instance is bootstrapped, closing a race where an early SSO login could permanently lock the operator out of the admin console.
  • The Helm chart now defaults networkPolicy.enabled: true (default-deny egress). It degrades gracefully on a CNI that doesn’t enforce NetworkPolicy.
  • Default deployment examples pin a released image tag instead of latest (compose, .env.example, docs); floating tags are noted as convenience-only.

Security

  • First-run bootstrap is race-safe. The bootstrapped state is claimed atomically alongside admin creation, and SSO provisioning + the /setup gate both key off it, so exactly one admin is ever created (verified under concurrent load).
  • Login no longer leaks account existence via timing. The unknown-user / SSO-only path now runs a dummy argon2id verification so it costs the same as a real wrong-password attempt.
  • Container images are vulnerability-scanned before publish. The release workflow runs Trivy (fail on HIGH/CRITICAL) between build and push.
  • CI/CD hardening: concurrency cancellation on PR workflows.
  • The one-time setup token is accessed atomically (atomic.Pointer), fixing a data race under concurrent /setup requests.

Changed

  • Ingress TLS enforcement is configurable (ingress.sslRedirect), and the docs recommend existingSecret (SOPS / External Secrets / Vault) as the primary way to supply secrets rather than plaintext values.yaml.

0.1.1 - Brand, distribution, and hardening

Added

  • Docker Hub distribution. The container image is mirrored to nx1x/egret-nest alongside GHCR, with floating latest / v0 / v0.1 tags, and the Docker Hub repo overview is kept in sync with the README.
  • Go fuzzing over the untrusted-input parsing paths, plus contributor onboarding docs.

Changed

  • New visual identity - an egret-in-flight mark across the icon, app-icon, logo (a self-contained dark-card lockup), favicon, and social preview; the README now leads with the logo.
  • Wider security policy in SECURITY.md - explicit safe harbor for good-faith research, response-time targets, coordinated disclosure, and reporter credit (plain email, no PGP required).

Security

  • Go toolchain 1.26.5 and refreshed digest-pinned Actions and base images (clears the stdlib advisories).

0.1.0 - first release

The optional self-hosted dashboard for Egret: ingest CI/CD runs and view egress over time, endpoint drift, and violations across your fleet, with multi-tenant access control. Ships as a single Go binary with embedded SQLite - no external services required.

Added

  • Run ingest + history. The Egret agent/Action POSTs each run; stored in embedded SQLite. Run list/detail, per-repo egress-over-time, org fleet view, and new-endpoint drift (inline-SVG sparklines, no JavaScript).
  • Authentication - one core, three providers. Local accounts (argon2id) with self-service TOTP 2FA, GitHub OAuth, and generic OIDC (Okta / Entra / Google), configurable via env or an admin UI (client secrets encrypted at rest, env always wins).
  • Authorization (multi-tenant RBAC). Organizations → repositories → runs, with fail-closed org membership (SSO authenticates identity; an admin grants access), per-org roles (owner/admin/member/viewer), and scoped, revocable ingest tokens.
  • Admin console. Settings, connect-a-repo, user management, audit log, live access log, and retention controls.
  • Deploy. Dockerfile, hardened docker-compose (+ optional nginx TLS), a Helm chart, healthcheck + backup commands, and a deployment guide.

Security

  • Hardened for crown-jewel data: native TLS (or behind a proxy), __Host- cookies, CSRF on every mutation, a strict CSP (script-src 'none'), argon2id password hashing, AES-256-GCM secrets at rest, HMAC-verified webhooks, token-gated metrics, and an audit trail.
  • SSRF-guarded OIDC: every OIDC fetch for a UI-configured issuer refuses internal addresses at dial time (closes DNS-rebinding and attacker-declared-endpoint holes).
  • Supply chain: digest-pinned base images, SHA-pinned Actions, container CVE scanning (Trivy), govulncheck, and CodeQL.